jfrog / cve-2024-3094-tools

37 stars 8 forks source link

Don't run ldd on untrusted binaries #15

Open neumann-paulmann opened 5 months ago

neumann-paulmann commented 5 months ago

The current script runs ldd on an untrusted binary sshd, which is the test subject for potential infection with a backdoor. This is unsafe.